Configure HIP Redistribution in Prisma Access (Strata Cloud Manager)
Focus
Prisma Access

Configure HIP Redistribution in Prisma Access (Strata Cloud Manager)

Table of Contents


Configure HIP Redistribution in Prisma Access (Strata Cloud Manager)

Learn how to redistribute HIP information.
HIP report redistribution is enabled by default in Strata Cloud Manager. To view the redistribution details or to disable redistribution, follow the steps below.
  1. In Strata Cloud Manager, view the redistribution diagram and, if required, edit it in Strata Cloud Manager by going to ConfigurationNGFW and Prisma AccessIdentity ServicesIdentity Redistribution and setting the Configuration Scope to Prisma Access.
  2. (Optional) Change the mobile user-to-service connection redistribution and the remote networks-to-service connection redistribution by clicking Edit to edit the default changes.
    HIP and User-ID-to-IP address redistribution are enabled by default.
    The changes you make here apply to both mobile user-to-service connection and remote network-to-service connection redistribution.
    Be sure not to configure any redistribution loops. For example, the service connection redistributes quarantined device information to the mobile users; if you configure quarantine list information to be sent from mobile users to service connections; you introduce a loop that could cause memory issues and slowness in the Prisma Access infrastructure.
  3. (Optional) Change the service connection-to-mobile user redistribution, by clicking Edit to edit the default changes; then, clicking Edit to add or remove the Quarantined Device List information redistribution.
    Note that the Configuration Scope changes to Mobile Users Networks.
  4. Optional) To change the service connection-to-remote network redistribution; click Edit to edit the default changes; then, clicking Edit to add or remove the HIP (Host Information Profile) or IP to Users information redistribution. Quarantine List redistribution is not available to redistribute for mobile users.
    Note that the Configuration Scope changes to Remote Networks.